Policy · pol-vendor
Vendor & IT Outsourcing Risk Policy
Controls (3)
| Control | Name | Domain |
|---|---|---|
| VEN-01 | Critical third parties are risk-assessed before onboarding and annually | Third-Party Risk |
| VEN-02 | Provider contracts include data protection and RBI audit clauses | Third-Party Risk |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | Third-Party Risk |